
This is not afd.sys's first time. It's the FOURTH exploited zero-day in that same driver since 2022: CVE-2024-38193 (also Lazarus) CVE-2025-21418 CVE-2025-32709 CVE-2026-68820 (Lazarus, FudModule) One component, nation-state favorite.
Post summary
The tweet indicates that the afd.sys driver has been the target of four zero-day exploits across multiple CVEs, suggesting ongoing active exploitation in the wild.

